Out of Bounds Write in MediaTek MAE Affecting System Privilege
CVE-2026-20441
6.7MEDIUM
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 2 March 2026
What is CVE-2026-20441?
The MediaTek MAE is vulnerable to an out of bounds write due to a missing bounds check, which may allow a malicious actor to escalate privileges locally. This exploitation does not require user interaction and can occur if the attacker has already acquired system privileges. To mitigate this risk, users are encouraged to apply the patch identified as ALPS10432500.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MT2718, MT6899, MT6991, MT8678, MT8793 Android 15.0
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
